Breach directory
LinkedIn Data Breach (2012)
The LinkedIn breach happened in 2012 and looked small at the time. Four years later the full set surfaced: 165 million email addresses with passwords that crackers broke almost as fast as they could download them.
- Accounts exposed
- 164,611,595
- When it happened
- 2012, approximate
- Added to Have I Been Pwned
- May 2016
- Data exposed (2012)
- Email addresses, passwords
- Passwords stored as
- SHA-1, unsalted
- Separate 2021 scrape
- 125,698,496 addresses with names, job titles and more, from public profiles
Breach data from Have I Been Pwned by Troy Hunt, licensed under CC BY 4.0.
Was your email address in the LinkedIn breach?
Put in the address on your LinkedIn profile, current or old. You will see if it is in either LinkedIn record and which other breaches carry it.
What happened
LinkedIn was hacked sometime in 2012; Have I Been Pwned gives only the year. At the time the damage looked contained: the incident was thought to have exposed about 6.5 million password hashes, without the email addresses that would make them usable. In May 2016 the whole set came up for sale for five bitcoins, a couple of thousand dollars, and it held 167 million accounts.
Troy Hunt wrote up what happened next on 24 May 2016. The price fell as copies spread. Crackers moved faster still: within days, about 86 percent of accounts had a recovered password, and over a million members turned out to share the same six-digit run of numbers as their password. LinkedIn emailed members, and was quoted as having invalidated the passwords of accounts created before the 2012 LinkedIn breach that had not been changed since.
Several people offered Troy Hunt the data within days, a sign it was circulating widely, so he loaded it into Have I Been Pwned: 164,611,595 unique addresses, added in May 2016.
In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later.
A second, unrelated LinkedIn record followed in 2021. Attackers scraped public profiles during the first half of that year, and LinkedIn’s June 2021 statement said plainly that it was not a data breach and no private member data was exposed. Have I Been Pwned lists it anyway, as 125,698,496 addresses, because the profiles were matched to email addresses and sold.
What was exposed
Two records, two very different sets of data. From the 2012 LinkedIn data breach come only email addresses and password hashes, but those are the two fields that open accounts.
No passwords are in the 2021 scrape. It pairs email addresses with names, job titles, education levels, genders, geographic locations and social media profiles. That is a ready-made list for fake recruiters: a job pitch that fits your title, sent to your personal address.
How the passwords were stored
LinkedIn stored its 2012 passwords as SHA-1 hashes without a salt. Unsalted means every member who chose the same password got the same hash, so one crack revealed every account sharing it, which is why a single common password could expose more than a million people at once.
SHA-1 is also fast, letting ordinary hardware try billions of candidates per second. Troy Hunt pointed out that the choice was already poor in 2012, and said he believed LinkedIn changed its hashing around the time of the original incident. That came too late for this set: if your LinkedIn password from that era was anything short of long and random, assume it is known.
Timeline
Sometime in 2012
Data taken. At the time only about 6.5 million hashes, without addresses, were thought exposed.
May 2016
Someone offers the full set of 167 million accounts for five bitcoins.
May 2016
Troy Hunt reports on 24 May 2016 that most passwords are already cracked and LinkedIn is sending reset emails.
May 2016
Have I Been Pwned adds 164,611,595 addresses from the LinkedIn breach.
Jun 2021
LinkedIn says the newly sold profile data was scraped, not breached.
Disclosure lag
About four years, and the full size became known only through the sale.
What to do now
Anything you used as a LinkedIn password before 2016 should be retired everywhere, because it is almost certainly in a cracked list now. Check the accounts you have had longest, your email above all, and add two-factor sign-in to LinkedIn itself.
For the 2021 record there is nothing to change, only something to watch: be wary of job offers and contact requests that know your title and school but arrive at an address you never put on your profile. Then run the free LeakNix check to find which other breaches hold that address.
Questions about the LinkedIn breach
When did the LinkedIn breach happen?
- Sometime in 2012; Have I Been Pwned records the year only. The data stayed out of sight until it was offered for sale in May 2016, when it reached Have I Been Pwned.
Is the 2021 LinkedIn data the same as the 2012 breach?
- No. In 2012 attackers took email addresses and password hashes. The 2021 set was scraped from public profiles, holds no passwords, and LinkedIn said it was not a breach of private data.
Were LinkedIn passwords cracked?
- Most of them, within days of the 2016 sale. They were unsalted SHA-1 hashes, and Troy Hunt reported about 86 percent of accounts with a recovered password soon after the data spread.
Related breaches
The LinkedIn data breach record here (164,611,595 accounts, 2012) is from Have I Been Pwned under CC BY 4.0, with no endorsement of LeakNix implied.
LeakNix